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• TRANSFER OF SECURITY DATA BETWEEN TWO MEMORIES 
TECHNICAL FIELD OF THE INVENTION 

5 The present invention relates to the field of safe transfer of security data from one memory 
to another In an electronic data processing environment. In particular the present 
Invention relates co a method of transferring data from a non-volatile memory to a working 
memory of an electronic data processing device, such an electronic data processing device 
as well as to a device for blocking write attempts. 
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DESCRIPTION OF RELATED ART 



The cellular phones of today have more and more different functions and applications in 
them. One such function is the possibility to make" economical transactions. In performing 
15 transactions there is normally used security data in the form of private encryption keys. 
The storage of these keys has to be safe and safeguarded from manipulation. 

in relation to cellular phones these keys have up Oil now been stored In so-called NOR 
flash memories. These known memories are of the type XIP (execute in place), which 

20 means that the keys are not moved from the memory. It Is today possible to block writing 
of the position of such keys on such a memory using hardware solutions. Such solutions 
monitor program execution and data access on the system bus Inside the phone. Software 
code that Is not part of the authenticated firmware of the device Is prevented from 
accessing the keys. These solutions assume that at least the firmware and possibly the 

25 keys are located In an XIP memory, so that address patterns on the bus are fixed for any 
given execution sequence. 

Such NOR flash memories are however relatively expensive, why there is a trend to 
replace them with so-called NAND flash memories, which are cheaper. These memories are 
30 however not of the XIP type, and In order to use the content stored on them, the content 
has to be moved or copied to a working memory of the phone. 

There Is therefore a need for being able to protect such security data from manipulation 
when It is being moved from the NAND flash memory to the working memory. 
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It is furthermore often desirable to provide such a protection Independently of the central 
processing of the unit, since otherwise other units such as a debugging unit, which Is often 
a part of the phone for development reasons, can Influence such security information. 
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SUMMARY OF THE INVENTION 

The present invention is thus directed towards solving the problem of protecting the 
security data from manipulation/ when it is moved from a non-volacile memory to a 
S working memory as well as after such relocation. 

This is achieved by copying data from the non-volatile memory to the working memory, 
which data includes security data to be write-protected, activating blocking of the security 
data in the working memory, monitoring all communication with the working memory, and 
10 blocking all write attempts to the copied security data stored in the working memory, 
where activating blocking, monitoring. rammujUcat^ 

performed Independently of the central processing unit of the data processing device, such 
that the central processing unit cannot manipulate the security data. 

15 ' One object of the present invention Is to provide a method that protects security data from 
manipulation when the data is moved from a non-volatile memory to a worldng memory as 
well as after such relocation. 

According to a first aspect of the present Invention, the object is achieved by a method of 
20 transferring data from a non-volatile memory to a working memory of an electronic data 
processing device, comprising the steps of: 

copying data from the non-volatile memory to the working memory, which data 
Includes security data to be write-protected, 
activating a blocking of the security data In the working memory, 
25 monitoring all communication with the working memory/ and • 

blocking all write attempts to the copied security data stored in the working 
memory, 

wherein at least the steps of activating a blocking, monitoring communication 
and blocking write attempts are performed independently of the central 
30 processing unit of the data processing device, such that the central processing 

unit cannot manipulate the security data. 

A second aspect of the present Invention is directed to a method including the features of 
the first aspect, wherein the area of the security data in the non-volatile memory is pre- 
35 defined and pre-stored In a device for blocking write attempts and used at least Jn relation 
to activating a blocking. 



A third aspect of the present Invention is directed towards a method including the features 
of the first aspect, wherein the step of copying data comprises copying only the security 
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data from the non-volatile memory to the working memory Independently of the central 
processing unit of the data processing device and copying any further data under the 
control of the -central processing unit of the device. 

5 A fourth aspect of the present Invention is directed towards a method Including the 
features of the third aspect, wherein the area of the security data In the non-volatile 
memory and the area for storage of the security data in the working memory are pre- 
defined and. wherein the step of activating a blocking of positions of the working memory Is 
triggered by me copying being made to the pre-defined area in the working memory and 

10 the blocking Is activated for said area. 

A fifth aspect of the present Invention is directed towards a method including the features 
of the first aspect, wherein the step of copying comprises copying all data from the non- 
volatile memory to the working memory under the control of the central processing unit of 
IS the device. 

A sixth aspect of the present invention Is directed towards a method Including the features 
of the fifth aspect, wherein the area of the security data In the non-volatile memory is pre- 
defined and wherein the step of activating a blocking is triggered by a first detection of 
20 copying of security data from the pre-defined area In the non-volatile memory to an" area 
of the working memory and the blocking is activated for that area of the working memory. 

A seventh aspect of the present Invention Is directed towards a method Including the 
features of the first aspect, wherein the step of blocking is achieved by changing the 
2S destination address of the data transferred to the working memory. 

An eighth aspect of the present Invention Is directed towards a method Including the 
features of the first aspect, further comprising the steps of disconnecting a debugging unit 
at least when copying the security data to the working memory and reconnecting the 
30 debugging unit when the blocking has been activated. 

Another object of the present invention is to provide a device for blocking write attempts 
to security data that protects security data from manipulation when the data Is moved 
from a non-volatile memory to a working memory as well as after such relocation. 

According to a ninth aspect of the present invention, this object Is achieved by a device for 
blocking write attempts to security data transferred from a non-volatile memory to a 
working memory in an electronic data processing environment that Includes a central 
processing unit and comprising: 



35 



4 

a monitoring unit arranged to: 

activate a blocking of the security data In the working memory upon copying of 
the security data from the non-volatile memory to the working memory, 
monitor all communication with the working memory, and 
5 block all write attempts to the copied security data stored In the working 

memory, 

all performed independently of the central processing unit of the data 
processing environment, such that the central processing unit cannot 
manipulate the security data. 

10 . 

A tenth aspect of the present invention is directed towards a. method including the features 
of the ninth aspect, wherein the area of the security data In the non-volatile memory is 
pre-defined and pre-stored in the device and used in relation at least to activating a * 
blocking. 

15 

An eleventh aspect of the present Invention is directed towards a device including the 
features of the ninth aspect, further comprising a copy control unit arranged to copy the 
security data from the non-volatile memory to the working memory also independently of 
' the central processing unit of the data processing environment. 

20 

,A twelfth aspect of the present invention is directed towards a device Including the 
features of the eleventh aspect, where the area of the security data in the non-volatile 
memory and the area for storage of the security data In the working memory are pre- 
defined and pre-stored In the device and the monitoring unit when activating a blocking is 
25 triggered by the copying being made to the pre-defined area in the working memory and 
activates a blocking of that area. 

A thirteenth aspect of the present invention is directed towards a device including the 
features of the ninth aspect, where the area of the security data in the non-volatlle 
30 memory Is pre-defined and pre-stored In the device and the monitoring unit when 

activating a blocking is triggered by a first detection of copying of security data from the 
pre-defined area In the non-volatile memory to an area of the working memory and 
actfvatlng a blocking for that area of the working memory. 

35 A fourteenth aspect of the present invention is directed towards a device Including the 
features of the ninth aspect, wherein the. monitoring unit is arranged to block write 
attempts by changing the destination address of data transferred to the" working memory 
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A fifteenth aspect of the present invention is directed towards a device Including the 
features of the ninth aspect, wherein the monitoring unit is arranged to disconnect a 
debugging unit of the electronic data processing environment at least when the security 
data is copied to the working memory and to reconnect the debugging unit when the 
5 blocking has been activated. 

A sixteenth aspect of the present invention Is directed towards a device Including the 
features of the ninth aspect, wherein It Is implemented in hardware. 

10 Yet another object is to provide an electronic data processing device that protects security 
data from manipulation when the data is moved from a non-volatile memory to a working 
memory as well as after such relocation- 
According to a seventeenth aspect of the present Invention, this object Is achieved by an 

15 electronic data processing device comprising: 

a non-volatile memory comprising data including security data to be write- 

protected, 

a working memory, 

a central processing unit arranged to control copying of at least some data 
20. from the non-volatile memory to the working memory, and 

a device for blocking write attempts to security data transferred from the 
non-volatile memory. to the working memory and comprising a monitoring 
unit arranged to: 

activate a biocklng of the security data In the working memory upon 
2S copying of the security data from the non-volatile memory to the 

working memory, 

monitor ail communication with the working memory, and 
block all write attempts to the copied security data stored in the 
working memory, 

30 all performed independently of the central processing unit, such that 

the central processing unit cannot manipulate the security data. 

An eighteenth aspect of the present Invention is directed towards a device including the 
features of the seventeenth aspect, wherein the area of the security data in the non- 
35 volatile memory Is pre-defined and pre-stored In the device for blocking write attempts 
and used in relation at least to activating a blocking. 

A nineteenth aspect of the present invention is directed towards a device including the 
features of the seventeenth aspect, wherein the device for blocking write attempts further 
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comprises a copy control unit arranged to copy the security data from the non-volatile 
memory to the working memory Independently of the centrat processing unit and the 
central processing unit is arranged to control the copying of further data from the non- 
volatile memory to the working memory. 

5 

A twentieth aspect of the present invention Is directed towards a device including the 
features of the nineteenth aspect, where the area of the security data In the non-volatile 
memory and the area for storage of the security data in the working memory are pre- 
defined and pre-stored In the device for blocking write attempts and the monitoring unit 
10 when activating a blocking is triggered by the copying being made to the pre-defined area 
in the working memory and activates a blocking of that area. 

A twenty-first aspect of the present Invention Is directed towards a device Induding the 
features of the seventeenth aspect, wherein the central processing unit is arranged to 
IS control the copying of all data from the non-volatile memory to the working memory. 

A twenty-second aspect of the present invention is directed cowards a device including the 
features of the twenty-first aspect, where the area of the security data in the non-volatile 
memory Is pre-defined and pre-stored in the device for blocking write attempts and the 
20 monitoring unit when activating a blocking is triggered by a first detection of copying of 
security data from the pre-defined area in the non-volatile memory to an area of the 
working memory and activating a blocking for that area of the working memory. 

A twenty-third aspect of the present invention is directed towards a device induding the 
25 features of the seventeenth aspect, wherein the monitoring unit is arranged to block write 
attempts by changing the destination address of data transferred to the working memory. 

A twenty-fourth aspect of the present Invention Is directed towards a device including the 
features of the seventeenth aspect, further comprising a debugging unit and wherein the 
30 monitoring unit Is arranged to disconnect the debugging unit at least when the security 
data is copied to the working memory and to reconnect the debugging unit when the 
blocking has been activated. 

A twenty-fifth aspect of the present Invention is directed towards a device induding the 
35 features of the seventeenth aspect, wherein the device for blocking write attempts is 
implemented In hardware. 
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A twenty-sixth aspect of the present Invention Is directed towards a device Including the 
features of the seventeenth aspect, wherein the device Is a portable communication 
device. 

5 A twenty-seventh aspect of the present Invention is directed towards a device including the 
features of the twenty-sixth aspect, wherein the device Is a cellular phone. 

The invention has the following advantages. It enables the storage of security data In a 
working memory without risking tampering of this data, which Is guaranteed by the 
10 independence from the central processing unit. Another advantage is that cheaper 

memories therefore can be used Instead of the memories that would otherwise be needed. 
It also allows the possibility to keep a debugging unit in the electronic data processing 
device for debugging software loaded' In the device Without having to compromise the 
safety of the security data. 
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It should be emphasized that the term ^comprises/comprising- when used in this 
specification Is taken to specify the presence of stated features, Integers, steps or 
components, but does not preclude the presence or addition of one or more other features, 
Integers, steps, components or groups thereof. 

BRIEF DESCRIPTION OF THE DRAWINGS 

The present invention will now be described In more detail In relation to the enclosed 
drawings, in which: 

25 .... ... 

fig. l shows a block schematic of an electronic processing device including a device for 
blocking write attempts both according to a first embodiment of the Invention, 
fig. 2 shows a flow chart of a method according to the first embodiment of the Invention, 
fig. 3 shows a block schematic of an electronic processing device including a device for 

30 blocking write attempts both according to a second embodiment of the invention, and 
fig. 4 shows a flow chart of a method according to the second embodiment of the 
Invention. 
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DETAILED DESCRIPTION OF EMBODIMENTS 

An electronic data processing device 10 according to a first embodiment of the invention Is 
shown in a block schematic in fig. 1. The device is preferably provided In a portable 
communication device and in the preferred embodiment the device Is provided in a cellular 
phone and then a so-called smartphone. A cellular phone Is Just one example of where the 
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invention can be implemented. The invention can for instance also be used in a PDA 
(personal digital assistant), a palm top computer, a lap top computer and in a PC (personal 
Computer). The device where the electronic data processing device according to the 
invention is Implemented should however have functionality for secure transferring and 
5 transactions. 

The device 10 Includes a communication bus 12 to which are connected a central 
processing unit 14, a device for blocking write attempts 16, a ROM memory 18 and an 
interface 20 towards external memories. The device 16 Includes a monitoring unit 28, the 

10 functioning of which will be described In more detail layer. To the interface 20 are 

connected a working memory 22, which preferably Is a volatile so-called SD RAM memory 
and a non-volatile NAND flash memory 24. A debugging unit 26 is also connected to the 
bus 12. The NAND flash memory Includes an area defined by memory addresses Al and 
A2, which area comprises security data 30 In the form of private cryptographic keys. The 

IS working memory 22 includes a corresponding area defined by memory addresses Bl and 
B2, which is to receive the private security keys. 

The main functioning of the electronic data processing device is, as is well known to the 
m an.sklHed. i n.ti,e.a rt ,to. execute seftW are^ored.4n. different- memcr^- under the- control 
20 of the centra, processing unit Some such software can be some type 

software originally stored In the NAND flash memory. The Information on a NAND flash 
memory cannot be used directly, but this information has to be transferred to a working 
memory before being used. If this is done in a straight-forward ^J^^T 
necessary precautions, this data can be tampered with, which is highly undesirable the 
25 data includes private keys to be used in for instance transactions involving money. One 
. such source of tampering can be the debugging unit, which is connected 

order to debug faulty programs. This- debugging unit often has contact with other devices, 
„ke computers and servers and can take control of the central processing un : of the 
electronic processing device and Is therefore a potential safety risk for the data that Is 
30 transferred. 

The device and method according to a first embodiment of the Invention takes care of 
some of these safety aspects. Therefore the performance of the device & 
first embodiment will now be explained with reference being made to fig. 2. wh,ch shows 
3S flow chart of a method according to this first embodiment of the Invention. 

At scart-up of the device 10 the data in the flash memory 24 has to be transferred to the 
working memory 22. which in this first embodiment Is done under the control of the 
central processing unit 14. Before this is done, the monitoring unit 28 In device for 



? 

blocking write attempts 16 disconnects or turns off the debugging unit 26, step 32, in 
order to safeguard that the security keys In the flash memory 24 will not be tampered with 
after copying. This turning off Is thus done Independently from the central processing unft 
14. Thereafter the monitoring unit 28 monitors the traffic on the bus 12, step 34. Traffic 
5 on the bus is sent using source and destination addresses. As mentioned before the 
copying of data is performed under the control of the central processing unit 14, step 36. 
This unit 14 therefore controls the ROM memory l8 r which Includes transferral codes for 
transferring all the data In the flash memory 24 to the working memory 22. Here the data 
from the flash memory 24 can be stored In any position in the working memory 22. The 
10 content of the flash memory 24 Is transferred sequentially. The monitoring unit 28 is set to 
look out for the memory addresses Al and A2 defining the area of the security keys 30 in 
the flash memory on the data bus 12. This information Is pre-set and pre-stored In the 
monitoring unit 28 and therefore provided beforehand' in the monitoring unit 28. When the 
first of the information is transferred from address Al to address Bl in the working 
15 memory, the monitoring unit begins activating blocking through storing the destination 
address Bl. It then waits until the last address A2 of the area Is transferred to destination 
address B2, which it also stores. The monitoring unit then locks the data area Bl - B2 of 
the working memory 22, since then the keys 30 have been copied. In this way blocking of 
the address area defined by addresses Bl and B2 was activated by the monitoring unit 
20 upon the first detection of data transfer from the area defined by addresses Al and A2, 
step 38. The monitoring unit then reconnects or turns on the debugging unit 26, step 40, 
so that it can function yet again. After this the monitoring unit 28 continues monitoring all 
the trafffc on the bus, step 42, and blocks all attempts to write to the area defined by 
addresses Bl and B2, step 44. This blocking is normally done through controlling the 
25 interface 20 to change address whenever a write command to any address in the area is 
encountered. Steps 38 - 44 ara all performed by the monitoring unit independently of the 
central processing unit 14. The device 16 Including the monitoring unit 28 Is provided in 
the form of hardware in the form of suitably selected and connected logic circuits. This 
makes the device 16 work fast. Another advantage is that the functioning of It cannot be 
30 changed, which makes Illegal tampering of the device hard, so that write-protection of the 
moved security keys can be guaranteed. 

Now a second embodiment of the Invention will be described with reference being made to 
fig, 3 and 4. Rg, 3 shows a device 10 that Is similar to the device In fig- 1. There Is only 
35 one difference here and that is that the device for blocking write attempts 16 also Includes 
a copy control unit 46. This unit 46, which In this embodiment Is a DMA (Direct Memory 
Access) unit, takes care of the transfer of the keys in the area Al - A2 in the flash memory 
24 to the area Bl - B2 of the working memory 22. As in the first embodiment, the 
monitoring unit 28 in device 16 here disconnects or turns off the debugging unit 26, step 
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48, In artier to safeguard that the private security keys 30 in the flash memory 24 will not 
be tampered with after copying. Thereafter the copy control unit 46 copies the keys 30 In 
the area defined by addresses Al and A2 in the flash memory 24 to the area defined by 
addresses Bl and B2 in the working memory 22, step 50, In this case both the addresses 
5 Al - A2 and addresses BX - B2 are pre-defined and pre-stored in the copy control unit 46 
and therefore provided beforehand, "me copy control unit 46 here also transfer this content 
sequentially, When the copy control unit 46 has copied these addresses it notifies the 
monitoring unit 28, which then goes on and activates blocking of the area defined by 
addresses Bl and B2, step 52. The monitoring unit 28 can also have these addresses Bl 
10 and B2 pre-stored or receive them from the copy control unit 46 upon signalling of finished 
copying. The monitoring unit 28 then reconnects or turns on the debugging unit 26, step 
54, so that It can function yet again. Thereafter the monitoring unit 28 starts monitoring all 
* the traffic on the data bus, step 56. The central processing unit 14 transfers the rest of the 

content from the flash memory 24 to the working memory 22, step 58, which Is done in 
IS the same way as was described In relation to the first embodiment. The monitoring unit 28 
then blocks all attempts to write to the area defined by addresses Bl and B2, step 60. This 
blocking Is done In the same way as was described in the first embodiment. Steps 48 - 56 
and 60 are all performed by the monitoring unit independently of the central processing 
unit. The device for blocking write attempts 16 including the copy control unit 46 and the 
20 monitoring unit 28 Is also here provided in the form of hardware for making illegal 

tampering of the device hard, so that write-protection of the moved security keys can be 
guaranteed. 

When the electronic data processing device is turned off, the working memory is emptied, 
25 which means that the data In the flash memory has to be transferred each, time the device 
Is turned on again or rebooted. 

: ^ present invention has many advantages. It enables the storage of the private security 
keys in a working memory without risking tampering of these keys, which Is guaranteed by 
30 the Independence of the central processing units. Another advantage is that cheaper 

memories therefore can be used Instead of the memories that would otherwise be needed. 
It also allows the possibility to keep a debugging unit in the device for debugging software 
loaded in the device without having to compromise the safety of the security keys. 

35 The present invention can be varied In many ways. The different method steps do not 
necessarily all have to be provided In the order described. It is however essential that the 
debugging unit is turned off before the keys are transferred and that the activating of a 
blocking or locking follows Immediately after the transfer of the keys. The flash memory 
can be included in the device or be an external memory that Is connected to the device. It 
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can also Include other data than the keys and any software associated with the keys. The 
working memory can of course also Include other types of information. It Is possible that 
the flash memory , m the first described embodiment can have the addresses of the defined 
area in the working memory stored at a specific location, which location the ROM memory 
5 then can access for finding out the destination address of the security keys. The invention 
Is furthermore not limited to private security keys, but can be applied on any data that 
needs to 6e write-protected. In view of this the present Invention is therefore only to be 
limited by the following claims. 



ABSTRACT 



The present Invention is directed towards a method of transferring data from a non-volatile 
memory (24) to a working memory (22) of an electronic data processing device (XO). such 

S an electronic data processing device as well as to a device for blocking write attempts 
(16). For this reason a monitoring unit (28) activates a blocking of the security data (30) 
in the working memory (22) upon copying of the security data from the non-volatile 
memory (24) to the working memory, monitors all communication with the working 
memory, and blocks all write attempts to the copied security data stored in the working 

10 memory, all performed independently of the central processing unit (14) of the data 
processing environment, such that the central processing unit cannot manipulate the 
. security data. 
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MONITOR TRAFFIC ON DATA BUS FROM MONITORING UNIT 
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COPY DATA FROM FLASH MEMORY TO WORKING 
MEMORY UNDER CONTROL OF CPU 
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ACTIVATE BLOCKING OF AREA Bl - B2 WHEN 
MONITORING UNIT DETECTS SECURITY DATA TRANSFER 
FROM AREA Al - A2 TO AREA Bl - B2 
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CONTINUE MONITORING TRAFFIC ON DATA BUS 
FROM MONITOR ING UNIT 
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BLOCK ALL WRITE AT TEMPTS TO AREA SI - B2 
FIG. 2 
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COPY SECURITY DATA FROM AREA Al - A2 TO 
AREA Bl - B2 USING DATA COPY CONTROL UNIT 
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ACTIVATE BLOCKING OF AREA Bl - B2 FROM 
MONITORING UNIT 
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"XI TURN ON DEBUGGING UNIT FROM MONITORING UNIT 
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MONITOR TRAFFIC ON DATA BUS FROM MONITORING UNIT 
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COPY REST OF DATA FROM FLASH MEMORY TO 
WORKING MEMORY UNDER CONTROL OF CPU 
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BLOCK ALL WRI TE ATTEMPTS TO AREA Bl - B2 
FIG. 4 



